@jbaruch @saturnism #OracleCodeOne #grafeas One Metadata to Rule Them All: Open Approach to Metadata for Better Releases The Grafeas Project @jbaruch @saturnism #OracleCodeOne #grafeas
@jbaruch @saturnism #OracleCodeOne #grafeas The speakers @jbaruch @saturnism @jbaruch @saturnism #OracleCodeOne #grafeas
@jbaruch @saturnism #OracleCodeOne #grafeas Do you Grafeas? Never heard about Grafeas Vaguely remember last year’s announcement Know about it, follow the news Use Grafeas I am Vincent Tsao @jbaruch @saturnism #OracleCodeOne #grafeas
@jbaruch @saturnism #OracleCodeOne #grafeas Grafeas what? API spec for managing metadata about software resources Container images VM images JAR files scripts Define and aggregate information @jbaruch @saturnism #OracleCodeOne #grafeas
@jbaruch #dockercon jfrog.com/shownotes Unified metadata Consume metadata from public sources NVDB Maven Central Produce metadata about private packages Jenkins JFrog Xray Combine metadata to product level Make decisions in runtime Kritis @jbaruch #dockercon jfrog.com/shownotes
@jbaruch #dockercon jfrog.com/shownotes Grafeas model Note Vulnerability License QA coverage Occurrence Instantiation of a note on an artifact @jbaruch #dockercon jfrog.com/shownotes
@jbaruch #dockercon jfrog.com/shownotes Component types Debian Docker Maven npm NuGet Python rpm Generic file @jbaruch #dockercon jfrog.com/shownotes
@jbaruch #dockercon jfrog.com/shownotes Anything beyond docs? Reference implementation https://github.com/grafeas/grafeas JFrog Xray https://www.jfrog.com/confluence/display/XRAY/Xray+REST+API#XrayRESTAPI-GRAFEAS Twistlock @jbaruch #dockercon jfrog.com/shownotes
Q&A and twitter aids @jbaruch @saturnism #OracleCodeOne #grafeas